Description
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing a malicious document, leading to a type confusion error that causes the application to crash. This results in a denial of service (DoS), making the affected system or application unavailable.
CVSS breakdown
CVSS 3.1
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected products
- ibm / aix7.2.5 – 7.2.5.12
- ibm / aix7.3.4 – 7.3.4
- ibm / vios4.1.0 – 4.1.1.30
- ibm / vios4.1.2.0 – 4.1.2.0
- RedHat / enterprise_linux10.0 – 10.0
- RedHat / enterprise_linux8.0 – 8.0
- RedHat / enterprise_linux6.0 – 6.0
- RedHat / enterprise_linux7.0 – 7.0
- RedHat / enterprise_linux9.0 – 9.0
- RedHat / hardened_images
- RedHat / jboss_core_services
- RedHat / openshift_container_platform4.0 – 4.0
- xmlsoft / libxml22.13.0 – 2.15.3
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:11503
- VENDOR_ADVISORYhttps://access.redhat.com/security/cve/CVE-2026-6732
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2461300
- MISChttps://gitlab.gnome.org/GNOME/libxml2/-/issues/1097
- MISChttps://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/411
Updated 8m ago · 8 sources